Database/Kernel, userspace & hypervisor
Linux kernel (arch/x86/kernel/fpu): A guest that disables an XSAVE feature through XFD while the saved XSTATE_BV still
Impact
A guest that disables an XSAVE feature through XFD while the saved XSTATE_BV still advertises it makes the host execute XRSTOR with a state combination that raises #NM in kernel context and panics the machine. One tenant's WRMSR takes the entire node down, which in a shared GPU cluster is every co-resident tenant's outage.
Who can reach it
Guest-side: the guest writes MSR_IA32_XFD to disable a feature (AMX and friends) and wins a race against a host interrupt that triggers kernel_fpu_begin() before KVM updates the guest XFD. Requires an XFD-capable CPU (Sapphire Rapids-class AMX hardware) and any tenant VM on it. A second path is a VMM stuffing XSTATE_BV via KVM_SET_XSAVE, which needs /dev/kvm.
What to do
Update to a kernel with the referenced stable commits. Interim: do not expose AMX / XFD-gated features in the guest CPU model on unpatched nodes, which removes the guest's ability to set XFD at all.
References
Related entries
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore pathCVE-2026-64460 · Linux kernel (drivers/pci)High
- Windows Server Services for NFS: use-after-free in the ONCRPC XDR driver gives local code executionCVE-2026-70585 · Windows Server Services for NFS (ONCRPC XDR kernel driver)High
- Linux kernel BPF verifier: JMP32 comparisons against zero mispredicted, allowing unsafe pointer arithmeticCVE-2026-98041 · Linux kernel BPF verifier (is_branch_taken, JMP32 pointer-vs-zero prediction)High
- Linux kernel BPF: per-CPU map updates accept invalid CPU IDs on sparse CPU masks, corrupting kernel memoryCVE-2026-98150 · Linux kernel BPF (BPF_F_CPU target-CPU validation in bpf_map_check_op_flags)High
- Linux kernel nvme-rdma: double cleanup and DMA unmap after request completion on the -EIO pathCVE-2026-98154 · Linux kernel nvme-rdma (queue_rq -EIO cleanup path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.